Answered: [Security threat] tags are not sanitized in extra question field

Post date: 2020-07-01 00:44:51
Views: 387

Hey q2apro, I think you are testing the default q_view_extra($q_view); function.

The default function is still safe. But if you pull the content from the databse, it's not safe.

First, look! The script is stored in database.

database

Second, if create a function to pull that content form the datase:

public function q_item_extra($q_item)
{
$postidz = $q_item'raw']'postid'];
$extra = qa_db_read_one_value(qa_db_query_sub(
       'SELECT content FROM ^postmetas WHERE title="qa_q_extra" AND postid=#',
        $postidz
   ), true);
 
 //$extra = $q_item'extra']'content'];
 
        $this->output('My info:'.$extra);   
   
}

Here's the result:

test

I hope you'll get my point.

Please click Here to read the full story.
 
Other Top and Latest Questions:
The SALT deduction limit is $40,400 for 2026. Here's how to maximize it
Americans grow more pessimistic about their finances, New York Fed finds — expert warns of ‘tough choices’ ahead
Anthropic will be 'most ridiculous IPO' of year, analyst says
Levi Strauss hikes profit guidance after tariff refunds, but its sales outlook is less optimistic
Stargate SG-1: Abyss Rewatch
Slow Horses: Lost and Found
Ted Lasso: Being Alive
Line of Fire: Pilot
Elon Musk blames Indian 'oligarchs' for stalling Starlink launch
Stock futures are little changed after S&P 500 retreats from record: Live updates